PRiSM
Security
Confidential & Proprietary.
Three Aspects of Security
●Authentication
● Who can log into PRiSM
●Security Groups
● What items can they view
●Security Roles
Confidential & Proprietary.
PRiSM Users
●Windows active directory
● Active directory user● Active directory user group
●Local machine accounts
● PRiSM Server only
●Security considerations
● PRiSM Stores only the windows system identifier (SID) ● Not usernames
Confidential & Proprietary.
Authentication Process
1. Collect SID from client machine
2. Compares SID to PRiSM database
● List of authorized users and groups ● List of authorized user groups
Confidential & Proprietary.
Client Computer PRiSM Server
Client Authentication - Web
Confidential & Proprietary.
Client Computer PRiSM Server
Client Authentication - Local
Confidential & Proprietary.
Anonymous Authentication
Confidential & Proprietary.
Administer Users
Confidential & Proprietary.
Confidential & Proprietary.
Confidential & Proprietary.
Security Groups
●Restricted View Access
● Assets● Templates ● Projects
Confidential & Proprietary.
Full Access Group
Confidential & Proprietary.
New Security Group
Confidential & Proprietary.
Details
●Group Name
● Name shown when configuring a user
Confidential & Proprietary.
Assets
●Allowed Assets
● Drag and drop from hierarchy to pane on right
● Add every asset or folder the user will have access to
●Deleting
● Click ID
Confidential & Proprietary.
Assets Access in Client
Confidential & Proprietary.
Assets Access in Web
Confidential & Proprietary.
Templates
Confidential & Proprietary.
Templates Access Application
Confidential & Proprietary.
Templates Access Application
●Users will be able to associate allowed templates only
Confidential & Proprietary.
Project Access
●Access to projects determined by asset and template access
● Asset (Default configuration)Confidential & Proprietary.
Project Access Example
Asset Only
● The user has been given asset to
● Allowed Asset ● Allowed Template
● Allowed Asset
● Project – No Template ● Project – Allowed Template ● Project – Restricted Template
● Restricted Asset
Confidential & Proprietary.
Project Access Example
Both Asset and Template
● The user has been given asset to
● Allowed Asset ● Allowed Template
● Allowed Asset
● Project – No Template ● Project – Allowed Template ● Project – Restricted Template
● Restricted Asset
Confidential & Proprietary.
Project Access Example
Either Asset or Template
● The user has been given asset to
● Allowed Asset ● Allowed Template
● Allowed Asset
● Project – No Template ● Project – Allowed Template ● Project – Restricted Template
● Restricted Asset
Confidential & Proprietary.
(Non-derived Template)
●Useful with Both Asset and Template or Either Template or Asset
configurations
Confidential & Proprietary.
Real Time Services Access
●Users will be able to view allowed real time services only
● PointsConfidential & Proprietary.
Service vs Service Type
Service Service Type
● Access to specific services ● Access to all services
Confidential & Proprietary.
RTS Access Application
Confidential & Proprietary.
RTS Access Application
Confidential & Proprietary.
RTS Access Application
●Trending
● Actual (Source RTS) cannot be used
Confidential & Proprietary.
Members
Confidential & Proprietary.
Administrator
●Administrator
Confidential & Proprietary.
Read Only
● Read Only Access
● View Projects ● View Templates ● View Alarms
● View Annunciators
● Read Only Restrictions
● System settings
● Service configuration ● User management ● Asset management
Confidential & Proprietary.
Custom
●Custom Roles
Confidential & Proprietary.
Role Details
●Client login
● Allows user to log into PRiSM Client
●Web login
● Allows user to log into PRiSM Web
●Modify Projects
● Create, edit, and delete projects
●Modify Templates
● Create, edit, and delete templates
●Clear Alarms (Manage Alarms)
Confidential & Proprietary.
Role Details
● Quick Train
● The allows users to quick train projects ● Also requires “modify projects”
● Modify Annunciator Panel
● Create, edit, and delete annunciator panels
● Modify System Preferences
● Edit system preferences in PRiSM client ● Edit system preferences in PRiSM web
● Modify User Preferences
Confidential & Proprietary.
Role Details
●Modify Real Time Services
● This allows users to configure RTSs
● Service administration and agent administration
●Modify Web Services
● This allows users to define external web data services
●Modify Local Configuration
● This allows users to open the local configuration file though the about screen and the local hosts file from the eDNA Configuration Screen
●Modify User Libraries
Confidential & Proprietary.
Role Details
●Manage Notifications
● This allows access to the general notification settings, notification format, and manage notification only account subscriptions.
●Manage Assets
● This allows access to the asset management screen and controls access to create new folders when changing project’s asset folder.
●Manage Users
Confidential & Proprietary.
Additional Administrator Role Access
●Administrator
Confidential & Proprietary.
Asset Role
●Allows a user’s role to be different in specific assets
●Example usage
● User’s default access is read only ● In a specific asset has user access
Confidential & Proprietary.
Asset Role
Confidential & Proprietary.